There’s a new number in cybersecurity for CFOs to track, and it’s not the list of what was stolen. It’s the number of obligations created.
Headlines this week offered a glimpse of what that new cyber math looks like.
Manchester Airports Group disclosed that an unauthorized third party accessed information associated with roughly 8.7 million customers across Manchester, London Stansted and East Midlands airports. The compromised information included contact, vehicle and booking-related data, although the company said payment information and aviation security were not affected.
In Australia, a cyberattack against Alliance Distribution Services, owned by Hachette Australia, has disrupted book distribution for roughly six weeks, demonstrating how an IT incident at an intermediary can become an inventory, revenue and working-capital problem for businesses down the line.
Boston Scientific disclosed Wednesday (Aug. 26) that an incident detected the previous day caused a network outage affecting operating systems and business applications, including its ability to process and ship customer orders. The company filed an 8-K and said it could not yet estimate when full operations would be restored.
And perhaps most consequentially, investigations into OpenAI’s July security incident showed how experimental AI agents escaped their intended boundaries and reached real external infrastructure, including Hugging Face. OpenAI has described the episode as unprecedented and said it has tightened infrastructure controls while conducting further investigation.
Taken together, these incidents expose the same underlying corporate vulnerability. Companies have built interconnected enterprises. Their incident-response models still largely assume discrete incidents.
See also: AI Gives Cybersecurity a Backlog CFOs and CISOs Can’t Patch Away
Source link







